4.3
CVSSv2

CVE-2008-1897

Published: 23/04/2008 Updated: 20/10/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The IAX2 channel driver (chan_iax2) in Asterisk Open Source 1.0.x, 1.2.x prior to 1.2.28, and 1.4.x prior to 1.4.19.1; Business Edition A.x.x, B.x.x before B.2.5.2, and C.x.x before C.1.8.1; AsteriskNOW prior to 1.0.3; Appliance Developer Kit 0.x.x; and s800i prior to 1.1.0.3, when configured to allow unauthenticated calls, does not verify that an ACK response contains a call number matching the server's reply to a NEW message, which allows remote malicious users to cause a denial of service (traffic amplification) via a spoofed ACK response that does not complete a 3-way handshake. NOTE: this issue exists because of an incomplete fix for CVE-2008-1923.

Vulnerable Product Search on Vulmon Subscribe to Product

asterisk asterisk business edition c.1.6.2

asterisk asterisk appliance developer kit 0.3

asterisk asterisk business edition b.2.2.0

asterisk open source 1.2.4

asterisk open source 1.2.8

asterisk asterisk appliance developer kit 0.6

asterisk open source 1.2.16

asterisk asterisk business edition c.1.6.1

asterisk open source 1.0.1

asterisk s800i 1.0.3.3

asterisk open source 1.2.14

asterisk s800i 1.0

asterisk s800i 1.0.2

asterisk open source 1.2.20

asterisk open source

asterisk open source 1.0.11

asterisk asterisk business edition c.1.0

asterisk open source 1.2.12

asterisk open source 1.2.19

asterisk asterisk business edition

asterisk open source 1.0.4

asterisk open source 1.0

asterisk open source 1.2.15

asterisk open source 1.2.9.1

asterisk open source 1.0.12

asterisk open source 1.4.10

asterisk open source 1.2.3

asterisk open source 1.2.23

asterisk open source 1.2.0

asterisk open source 1.2.26.2

asterisk asterisk appliance developer kit 0.6.0

asterisk open source 1.4.0

asterisk open source 1.2.26.1

asterisk open source 1.4.15

asterisk open source 1.0.2

asterisk open source 1.2.13

asterisk open source 1.2.25

asterisk open source 1.2.1

asterisk open source 1.2.26

asterisk asterisk business edition b.2.3.1

asterisk open source 1.2.24

asterisk open source 1.4.12.1

asterisk s800i 1.1.0

asterisk open source 1.0.3.4

asterisk open source 1.4.12

asterisk open source 1.4.16.2

asterisk s800i 1.1.0.1

asterisk asterisk business edition c.1.6

asterisk open source 1.0.6

asterisk open source 1.4.13

asterisk open source 1.2.18

asterisk open source 1.2.10

asterisk open source 1.2.11

asterisk open source 1.4.10.1

asterisk open source 1.4.18.1

asterisk open source 1.2.7.1

asterisk asterisk business edition b.2.5.0

asterisk asterisk business edition b.2.3.3

asterisk asterisk appliance developer kit 0.7

asterisk open source 1.2.2

asterisk open source 1.2.6

asterisk open source 1.4.1

asterisk open source 1.2.5

asterisk asterisk appliance developer kit 0.4

asterisk open source 1.0.5

asterisk open source 1.0.3

asterisk s800i 1.0.3

asterisk open source 1.4.11

asterisk open source 1.2.21

asterisk open source 1.0.9

asterisk asterisk business edition b.1.3.2

asterisk s800i

asterisk open source 1.0.7

asterisk asterisknow

asterisk open source 1.2.7

asterisk s800i 1.0.1

asterisk asterisknow 1.0.1

asterisk open source 1.2.17

asterisk asterisk business edition b.1.3.3

asterisk asterisk business edition b.2.3.4

asterisk open source 1.0.8

asterisk open source 1.4.18

asterisk asterisk business edition b.2.3.6

asterisk open source 1.2.22

asterisk open source 1.4.16

asterisk asterisk appliance developer kit 0.8

asterisk open source 1.4.14

asterisk open source 1.2.12.1

asterisk open source 1.2.9

asterisk open source 1.4.16.1

asterisk open source 1.2.21.1

asterisk open source 1.0.0

asterisk asterisk business edition b.2.2.1

asterisk asterisk business edition a

asterisk asterisk appliance developer kit 0.5

asterisk asterisk appliance developer kit 0.2

asterisk asterisk business edition b.2.3.2

asterisk open source 1.0.11.1

asterisk open source 1.4.17

asterisk asterisknow 1.0

Vendor Advisories

Joel R Voss discovered that the IAX2 module of Asterisk, a free software PBX and telephony toolkit performs insufficient validation of IAX2 protocol messages, which may lead to denial of service For the stable distribution (etch), this problem has been fixed in version 1213~dfsg-2etch4 For the unstable distribution (sid), this problem has been ...

References

CWE-287http://www.altsci.com/concepts/page.php?s=asteri&p=2http://bugs.digium.com/view.php?id=10078http://downloads.digium.com/pub/security/AST-2008-006.htmlhttp://secunia.com/advisories/29927http://www.debian.org/security/2008/dsa-1563https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00581.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-April/msg00600.htmlhttp://www.securityfocus.com/bid/28901http://www.securitytracker.com/id?1019918http://secunia.com/advisories/30010http://secunia.com/advisories/30042http://secunia.com/advisories/34982http://security.gentoo.org/glsa/glsa-200905-01.xmlhttp://www.vupen.com/english/advisories/2008/1324https://exchange.xforce.ibmcloud.com/vulnerabilities/41966http://www.securityfocus.com/archive/1/491220/100/0/threadedhttps://github.com/jcollie/asterisk/commit/771b3d8749b34b6eea4e03a2e514380da9582f90https://github.com/jcollie/asterisk/commit/a8b180875b037b8da26f6a3bcc8e5e98b8c904d2https://github.com/kaoru6/asterisk/commit/1fe14f38dd43dc894d21f85762b51208ba5c8acbhttps://github.com/lyx2014/Asterisk/commit/0670e43c30135044e25cca7f80e1833e2c128653https://github.com/silentindark/asterisk-1/commit/fe8b7f31db687f8b9992864b82c93d22833019c7https://github.com/xrg/asterisk-xrg/commit/10da3dab24e8ca08cf2c983f8d0206e383535b5ahttps://github.com/pruiz/asterisk/commit/e0ef9bd22810c6969a7f222eec04798f19a7e2d6https://github.com/xrg/asterisk-xrg/commit/51714a24347dc57f9a208a4a8af84115ef407b83https://github.com/mojolingo/asterisk/commit/20ac3662f137dbf7f42d5295590069a7d3b1166bhttps://downloads.asterisk.org/pub/security/AST-2008-006.htmlhttps://github.com/jcollie/asterisk/commit/60de4fbbdf3ede49f158e23a9e3b679f2e519c1ehttps://nvd.nist.govhttps://www.debian.org/security/./dsa-1563